M&A Due Diligence

Know the cyber risk you are buying.

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

Cyber Diligence for the Decision in Front of You

The work scales with the stage of the transaction. Early review identifies what is visible and what remains unknown; deeper diligence verifies the controls and builds the post-close plan.

5-day initial risk review

A bounded early view of available evidence, visible exposure, disclosed incidents and obligations, material red flags, and the questions that require management access.

Management-access diligence

Controls, architecture, critical data, resilience, compliance, third parties, key-person dependencies, and remediation needs reviewed at the depth the transaction allows.

Decision-ready reporting

An investment-committee narrative that separates verified facts, unresolved evidence gaps, plausible exposure, and the decisions the deal team needs to make.

100-day security planning

A sequenced post-close roadmap with priorities, owners, dependencies, and governance so diligence findings become managed work rather than shelfware.

Engagement path: 5-day Initial Risk Review, deeper diligence when management access is available, and an optional 100-day post-close security plan.

Theodolite decision overview showing control implementation, financial risk context, top priorities, and environment evidence

Evidence, with Limits Stated

Theodolite can accelerate evidence review. It does not manufacture certainty.

When the target environment and current source coverage fit, Theodolite can help organize verified control evidence, implementation status, findings, and priorities for the diligence team.

Interviews, documents, source access, and operator judgment still determine what can be concluded. The deliverable separates verified facts from assumptions and missing evidence so the investment committee can see both the risk and the confidence behind the assessment.

Review current source coverage →

How It Works

  1. 5-Day Initial Risk Review

    A bounded early view for the deal team: available evidence, visible exposure, disclosed incidents and obligations, material red flags, and the questions that need management access.

  2. Management-Access Diligence

    Go deeper into controls, architecture, data, resilience, compliance, third parties, key-person dependencies, and remediation requirements once the transaction process allows it.

  3. Investment Decision and 100-Day Plan

    Translate the findings into an investment-committee narrative, input for counsel and insurance discussions, and a sequenced post-close security plan with clear owners.

Who This Is For

Built for the deal side of the table and for portfolio leaders who need diligence findings translated into decisions and post-close work.

  • Private Equity and Venture Capital

    Sponsors evaluating a new investment, monitoring a portfolio company, or preparing an asset for exit.

  • Corporate Acquirers

    Deal and integration teams that need to understand inherited cyber risk, regulatory exposure, and post-close priorities.

  • Investment and Capital Partners

    Banks, family offices, and direct investors seeking an independent cybersecurity view alongside financial and legal diligence.

  • Portfolio Company Leaders

    Management teams preparing for buyer scrutiny or translating diligence findings into an executable remediation plan.

Leadership You Can Trust

Most advisors diagnose. Operators prescribe.

vCSO.ai is led by Nick Shevelyov, former CSO and CIO of Silicon Valley Bank and author of Cyber War and Peace. He brings the perspective of an enterprise operator, board director, and advisor to investors and cybersecurity companies.

Nick Shevelyov

Achievements

  • Defended Silicon Valley Bank’s cyber posture for 15 years (2007-2021), through every major crisis from the 2008 financial collapse to SolarWinds.
  • Design partner and advisor to category-defining cybersecurity companies including Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium.
  • Forbes Technology Council member, NASDAQ board director (AuthID), author of Cyber War…and Peace.
  • Founder of the CISO Supper Club, convening Bay Area cybersecurity executives twice a year.
Contact our team

Who You’ll Work With

Nick leads the deal-side judgment. Program management, GRC, technical assessment, and product specialists support the scope as the evidence and transaction stage require.

Mike Korsak

Mike Korsak

Senior Program Management Advisor

Berk Algan

Berk Algan

Governance, Risk & Compliance

Andrej Bosanac

Andrej Bosanac

Technical Assessments & Pen Testing

Nicholas Carlson

Nicholas Carlson

Product & Assessment Platform

Trusted by security leaders

What CISOs, founders, and risk leaders say about working with Nick.

“Nick has been an invaluable partner in elevating Audubon's cybersecurity strategy. His ability to provide clear, level-headed advice has been instrumental during tough moments, and his executive-level communication skills have been particularly effective for the org to plan for right-sized investments in cybersecurity.”
Marco Carbone
CTO, National Audubon Society
“Nick and team have been amazing partners to Pixee. Their knowledge, relationships, and industry experience have been a core part of our go-to-market strategy and refinement.”
Surag Patel
CEO, Pixee
“Nick and team provide a unique value blending cultural enablement and a risk-focused cyber risk management strategy. Their approach helped our team rapidly improve the effectiveness of our cyber risk program with quantifiable results.”
Alexander Trafton
SVP Technology Risk and Compliance, G42

FAQ

Questions deal teams ask before engaging.

What is cybersecurity due diligence?

Cybersecurity due diligence evaluates how a target protects critical systems and data, meets its obligations, responds to incidents, and carries risk into a transaction. The purpose is to support the investment decision and post-close plan, not to produce a generic IT audit.

What does the 5-day Initial Risk Review include?

It is a bounded review of the evidence available at that stage of the deal. It identifies visible exposure, material gaps, disclosed incidents and obligations, priority follow-up questions, and the areas that require deeper management-access diligence. Exact coverage is confirmed at intake because source access varies by transaction.

Can you work before management access is available?

Yes, with limitations. An external and document-based review can support an early bid or investment-committee discussion, but it cannot verify internal controls that are not observable or evidenced. Those limitations are stated clearly in the deliverable.

How does Theodolite fit the engagement?

Theodolite can support evidence collection and control review when the target environment, source access, and current product coverage fit. It does not replace interviews, document review, professional judgment, or the need to state evidence gaps.

Do you draft transaction or insurance terms?

No. We explain the cybersecurity findings, likely remediation needs, and decision implications so the deal team, counsel, brokers, and insurers can address them in their own work.

Can you stay involved after close?

Yes. The diligence can lead into a 100-day security plan or ongoing Strategic Oversight for program leadership, remediation governance, and board reporting.

What does the deal team need to know, and by when?

Share the transaction stage, decision date, target profile, and evidence currently available. We will define what can be responsibly concluded in the initial review and what requires deeper access.

Contact us We’ll be in touch →